RELEASE NOTES & SECURITY REPORTS

Free scanners, vulnerability reports, and platform-specific guidance. No fluff.

Vibe Coding Security Weekly — May 18, 2026: 1,764-App Audit Confirms RedAccess, Cursor Ships Bugbot, Mini Shai-Hulud Hits 169 npm Packages | VibeEval
2026.05.18 · 8 MIN READ ·

Download: vibe-coding-security-weekly-may-18-2026.pdf — printable, site-styled (7 pages).

A second independent audit dropped this week and …

SCANNER
2026 AI Coding Security Report: The Data Behind the Vibe-Coding Breach Wave | VibeEval
2026.05.13 · 13 MIN READ ·

This is the 2026 AI coding security report. It is built on 1,812 firehose events drained across 7.5 days (May 6 → May 13, 2026), every claim …

SCANNER
Vibe Coding Security Weekly — May 11, 2026: RedAccess Finds 380K Exposed Apps, TrustFall Hits AI Agents, Replit Ships Security Agent | VibeEval
2026.05.11 · 7 MIN READ ·

The week vibe-coding security broke into mainstream press. RedAccess scanned 380,000 publicly accessible apps built with Lovable, Base44, …

SCANNER
Lovable Security Report May 2026: The Defender Stack Reorganizes Around Vibe Coding | VibeEval
2026.05.11 · 8 MIN READ ·

May 2026 was the month the defender side of vibe-coding security finally shipped. Replit pushed out Security Agent and Workspace Security …

SCANNER
Vibe Coding Security Weekly — May 5, 2026: Replit vs Apple Goes Legal, Mythos Finds 271 Firefox Bugs, Gemini CLI CVSS-10 RCE | VibeEval
2026.05.05 · 6 MIN READ ·

The week of April 28 to May 5, 2026 turned every previous thread in vibe-coding security into something with teeth. Replit’s CEO …

SCANNER
VibeEval vs Competitors: The 2026 AI-Codegen Security Scanner Landscape
2026.05.02 · 8 MIN READ ·

Most security scanners are built for code from 2018. The AI-codegen apps shipping in 2026 are a different shape, fail in different ways, and …

SCANNER
After Testing Every Major LLM, None Ship Validation That Survives the First Pass | VibeEval
2026.05.02 · 7 MIN READ ·

If your AI-generated app passes Snyk, Semgrep, and the Claude Code or Codex review skill, you have proof that the code in your repo is …

SCANNER
Vibe Coding Security Weekly — Apr 30, 2026: Apple Blocks Vibe-Coding Updates, Claude Code Source-Map Leak, Lovable Goes Mobile | VibeEval
2026.04.30 · 5 MIN READ ·

Three stories defined vibe-coding security between April 28 and April 30, 2026: Apple’s quiet enforcement push against vibe-coding …

SCANNER
Lovable Security Report April 2026: 380K Apps Scanned, 5K Leaking, 5 Brands Phished on Lovable's Domain | VibeEval
2026.04.30 · 8 MIN READ ·

380,000

Vibe-coded assets RedAccess found publicly accessible (Lovable, Base44, Replit, Netlify)

5,000

Of those exposing genuinely sensitive …

SCANNER
Vibe Coding Security Weekly — Apr 28, 2026: Wiz Red Agent, SecureVibeBench, Red Gate's DB Failure Patterns | VibeEval
2026.04.28 · 6 MIN READ ·

Five stories shaped vibe-coding security between April 24 and April 28, 2026: Wiz’s Red Agent + AI-BOM launch at Google Cloud Next, …

SCANNER
Vibe Coding Security Weekly — Apr 23, 2026: Lovable 48-Day Leak, Anthropic MCP RCE, Gitar Launch | VibeEval
2026.04.23 · 6 MIN READ ·

Five stories shaped vibe-coding security between April 16 and April 23, 2026: a 48-day Lovable chat-history exposure, an Anthropic MCP …

SCANNER
Your CLAUDE.md Is Attack Surface: Snyk ToxicSkills + MCP Prompt Injection | VibeEval
2026.04.20 · 4 MIN READ ·

Snyk scanned 3,984 agent skills: 13.4% had critical security issues, 76 were malicious payloads. A March 2026 arXiv paper tested MCP clients …

SCANNER
When Beauty Bloggers Explain RLS, Vibe Coding Is Baseline | VibeEval
2026.04.20 · 3 MIN READ ·

A non-coder shipped a beauty app with Claude Code. Her blog has a whole section teaching RLS via apartment analogy. When beauty bloggers are …

SCANNER
Vercel Breach via Context.ai: Your AI Stack Is Now Your Supply Chain | VibeEval
2026.04.20 · 3 MIN READ ·

Vercel confirmed a breach. Entry point: a third-party AI tool (Context.ai) an employee was using — attackers owned the tool, then his Google …

SCANNER
Prompt Injection Turns AI Coding Agents Into Key Exfiltrators | VibeEval
2026.04.20 · 3 MIN READ ·

Security researchers prompt-injected AI coding agents from Anthropic, Google, and Microsoft integrated into GitHub Actions and walked out …

SCANNER
Lovable BOLA: The $6.6B Vibe-Coding Platform Just Got Vibe-Coded | VibeEval
2026.04.20 · 4 MIN READ ·

Lovable ($6.6B valuation) just shipped a BOLA. Change a project ID in the URL, free account, pull anyone’s entire source tree. .env …

SCANNER
Kiro IDE: Vibe-Coding Fix or Compliance Gate in AI Cosplay? | VibeEval
2026.04.20 · 3 MIN READ ·

Kiro IDE’s pitch: force docs upfront, scan on save, “eliminate vibe-based coding errors.” Translation: vibe coders ship …

SCANNER
DeepKeep Launches Vibe AI Red Teaming. Red Teaming Is Now Vibe-ified. | VibeEval
2026.04.20 · 3 MIN READ ·

DeepKeep just launched “Vibe AI Red Teaming” — human-in-the-loop attacks on AI apps and agents. CTO: “Just as vibe coding …

SCANNER
Broken by Default: AI Coding Assistants Fail 55.8% of Security-Critical Prompts | VibeEval
2026.04.20 · 5 MIN READ ·

Z3-verified study: AI coding assistants generate vulnerable code 55.8% of the time. Semgrep/Bandit/CodeQL catch 2.2%. Security prompts move …

SCANNER
Lovable + Aikido Pentesting: $100 Security Test vs VibeEval's Free Scanner | VibeEval
2026.03.31 · 6 MIN READ ·

Lovable just announced built-in penetration testing powered by Aikido Security. At $100 per test, it’s a fraction of traditional …

SCANNER
Apple vs Vibe Coding: Anything App Removed, Replit and Vibecode Blocked | VibeEval
2026.03.31 · 7 MIN READ ·

Apple removed “Anything” — a $100M vibe coding app — from the App Store and blocked updates for Replit and Vibecode. The AI …

SCANNER
Free Windsurf Security Scanner - Find Vulnerabilities in 60 Seconds
2026.03.12 · 5 MIN READ ·

Windsurf’s Cascade and agentic flows let you build full-stack apps fast. But the AI-generated code ships with security blind spots …

SCANNER
Free GitHub Copilot Security Scanner - Find Vulnerabilities in 60 Seconds
2026.03.12 · 5 MIN READ ·

GitHub Copilot is the most widely used AI coding assistant. But studies show a significant percentage of its suggestions contain security …

SCANNER
Free Firebase Studio Security Scanner - Find Vulnerabilities in 60 Seconds
2026.03.12 · 5 MIN READ ·

Firebase Studio makes it easy to build full-stack apps with Google’s AI. But the generated Firestore rules and Cloud Functions often …

SCANNER
Lovable Security Report Feb 2026: 18,000 Users Exposed, 170+ Databases Breached | VibeEval
2026.02.28 · 8 MIN READ ·

18,697

User records exposed in one app

170+

Databases fully exposed out of 1,645 scanned

90%

Of audited apps share same 5 vulnerabilities …

SCANNER
Free Cursor Security Scanner - Find Vulnerabilities in 60 Seconds
2026.02.28 · 5 MIN READ ·

Test Your Cursor Project Now

Enter your deployed app URL to check for security vulnerabilities in Cursor-generated code

Quick fact: …

SCANNER
VibeEval Security Scanner vs Reka Vibe-Eval Benchmark | Not the Same Product
2026.01.27 · 5 MIN READ ·

If you searched for “Vibe Eval” and landed here wondering about multimodal AI benchmarks, you’re in the wrong place.** …

SCANNER
07
Is Replit Secure? Free Security Scanner for Replit Apps
2026.01.07 · 5 MIN READ · Replit's instant deploy is magical — and magically hides exposed keys, missing auth, and injection-ready endpoints.
REPLIT SCANNER
06
Figma Make Security Scanner - Secure Your AI-Generated Code
2026.01.07 · 5 MIN READ · When designs become code, AI makes implicit assumptions about data handling and auth. Those assumptions are often unsafe.
FIGMA-MAKE SCANNER
05
Claude Code Security Scanner - Secure Your AI-Generated Code
2026.01.07 · 5 MIN READ · Claude Code can generate thousands of lines of code in minutes. Security review can't keep pace without AI-powered testing.
CLAUDE-CODE SCANNER
04
V0 Security Scanner - Test Your Vercel V0 Components Free
2025.06.14 · 4 MIN READ · V0 ships polished React components fast. Validation, state handling, and XSS sanitization get glossed over.
V0 SCANNER
03
Is Base44 Safe? Free Security Scanner for Base44 Apps
2025.06.14 · 5 MIN READ · Base44's AI app builder is production-capable with proper security testing — auth, API endpoints, session handling.
BASE44 SCANNER
01
Free Lovable Security Scanner - Find Vulnerabilities in 60 Seconds
2025.06.14 · 9 MIN READ · Over 1,430 Lovable apps scanned. 5,711 vulnerabilities found. Missing RLS is #1. Deep dive on RLS per-op checks + the 6 Vibe Coding flows …
LOVABLE SCANNER
02
Bolt.new Security Scanner - Free Vulnerability Check in 2 Minutes
2025.06.14 · 4 MIN READ · Full-stack AI generates frontend, backend, and database logic in seconds. Security gaps emerge between the layers.
BOLT SCANNER
VibeEval: A Vibe-Friendly Alternative to Snyk for Testing AI-Generated Apps
2025.05.12 · 5 MIN READ ·

VibeEval is your go-to tool for catching bugs, securing your code, and stress-testing your vibe-coded apps built with tools like Lovable and …

SCANNER
VibeEval for Testing Vibe-Coding Apps with Lovable, Cursor, and Bolt
2025.05.08 · 5 MIN READ ·

VibeEval is your go-to tool for catching bugs, securing your code, and stress-testing your vibe-coded apps built with tools like Lovable, …

SCANNER